cbcvebase.
CVE-2026-1767
published 2026-06-16

CVE-2026-1767: A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit…

PriorityP345high8.1CVSS 3.1
AVNACLPRLUINSUCHINAH
EPSS
0.25%
15.7th percentile
A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calculation during the parsing of performer tags can lead to a read beyond the allocated buffer, potentially causing a Denial of Service (DoS) due to a crash or enabling information disclosure.

Affected

5 ranges
VendorProductVersion rangeFixed in
debianlocalsearch< localsearch 3.8.2-12 (forky)localsearch 3.8.2-12 (forky)
debiantracker-miners< localsearch 3.8.2-12 (forky)localsearch 3.8.2-12 (forky)
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.